Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Redirect DNS queries

    Scheduled Pinned Locked Moved DHCP and DNS
    6 Posts 2 Posters 376 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      reynold
      last edited by reynold

      Hi, I installed pfblocker and I need to make dns redicrect.
      All DNS queries have to be forwarded to dns resolver in pfsense.
      I made two rules.
      DNS rules
      It seems working but i I read pfsense documentation ant it talks about NAT
      https://docs.netgate.com/pfsense/en/latest/recipes/dns-redirect.html
      Do i have to add NAT rule?
      thanks

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @reynold
        last edited by

        @reynold
        Redirecting DNS requests ensures that the client succeed to resolve the host name, even if he try to use any other DNS server. The request is redirected to pfSense, resolved and pfSense responses with the origin requested server IP.
        So the client doesn't complain that he is not able to resolve.

        R 1 Reply Last reply Reply Quote 1
        • R
          reynold @viragomann
          last edited by

          @viragomann
          ok, thanks a lot, so the difference is that:
          1)if i set up my dns on 8.8.8.8 and i do not enable redirect my client won' t resolve
          2)if i set up my dns on 8.8.8.8 and i enable redirect client will resolve domain but it will use pfsense and not google dns
          Is that correct?

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @reynold
            last edited by

            @reynold
            Yes, correct.
            The client will not notice, that the request was not responded by Google in fact.

            To prevent that the clients use DoH you can configure suitable pfBlocker lists.

            R 1 Reply Last reply Reply Quote 1
            • R
              reynold @viragomann
              last edited by reynold

              @viragomann
              Yes, I enabled lists for doh.
              Should I also configure rules for port 853 ? (DNS over TLS) ?

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @reynold
                last edited by

                @reynold
                I've just blocked it with a floating rule for all internal interfaces.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.